solid / solid/solid-oidc

Solid OIDC Security Consideration Client Secrets

Open
#129 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

doc: solid-oidc editorial
Dominant language
Bikeshed
Stars
26
Forks
14
PR merge metrics
No merged PRs in 30d

Description

In #security-client-secrets:

Client secrets SHOULD NOT be stored in browser local storage.

Perhaps "browser or application"? Clarify what's intended with "local" - specific to localStorage or sessionStorage or using it generally?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the #security-client-secrets section referenced in the issue and review the sentence about client secrets in browser local storage. Determine whether the intended scope is browsers, applications, localStorage, sessionStorage, or local storage generally. Done means the specification wording clearly reflects the intended security guidance.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, documentation
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.